Privacy Policy for Euphile Platform
Introduction
This Privacy Policy explains how revzper SAS processes your personal data in compliance with applicable data protection regulations.
1. Purpose of the Policy
This policy applies to all products under the Euphile platform operated by revzper SAS.
Data Controller and Data Protection Contact
1. Identity of the Data Controller
The data controller is revzper SAS, SIREN 945 219 186, with registered office at 60 rue François Ier, 75008 Paris, France.
2. Data Protection Contact
revzper SAS has designated a data protection contact to handle inquiries and requests related to this policy and data protection matters. Contact: privacy@revzper.com.
3. Scope of Products
All products under the Euphile platform are operated by revzper SAS. For product-specific inquiries, contact the data protection contact.
Purposes and Legal Bases for Processing
1. Service Provision and Maintenance
Processing is necessary for providing and maintaining services, including account management and customer support.
Ref: GDPR Art. 6(1)(b)
2. Marketing and Service Communications
Processing for marketing communications requires consent. Service-related communications rely on legitimate interests. Opt-out mechanisms are provided for both categories.
Ref: GDPR Art. 6(1)(a), GDPR Art. 6(1)(f)
3. Service Improvement
Processing for analytics and user feedback relies on legitimate interests with an option to opt-out.
Ref: GDPR Art. 6(1)(f)
4. Legal Compliance
Processing is necessary to comply with legal obligations such as tax reporting and fraud prevention.
Ref: GDPR Art. 6(1)(c)
Categories of Personal Data Processed
1. Identifying Data
Name, email address, phone number, postal address, and account credentials.
2. Technical Data
IP address, device identifiers, browser type, operating system, and cookies.
3. Usage Data
Interaction with services, transaction history, and support requests.
4. Financial Data
Payment details processed by third-party service providers.
5. Communication Data
Content of emails, chat messages, or other communications with support team.
6. Third-Party Data Processors
1. Comprehensive Processor List
A full list of third-party processors, their roles, and data processing agreements is available at Third-Party Processor List.
2. Categories of Processors
Processors are engaged in categories such as payment services, analytics, communication platforms, identity verification, and hosting services.
3. Safeguards for International Transfers
Safeguards include Standard Contractual Clauses and compliance with EU adequacy decisions.
4. Processor-Specific Inquiries
For details about specific processors, contact the data protection contact at privacy@revzper.com.
Data Subjects' Rights
1. Summary of Rights
You have the right to access, rectify, erase, restrict processing, port data, and object to processing based on legitimate interests.
Ref: GDPR Art. 15, GDPR Art. 16, GDPR Art. 17, GDPR Art. 18, GDPR Art. 20, GDPR Art. 21
2. Exercising Rights
Submit a written request to the data protection contact at privacy@revzper.com. Include your full name, contact details, and a clear description of the right(s) you wish to exercise.
3. Response Timeline
We will respond to your request within 30 days of receipt. Additional time may be required with explanation.
4. Lodging a Complaint
You may lodge a complaint with the CNIL (French Data Protection Authority) at commission@cnil.fr or via their website.
Data Retention
1. Retention Principles
Personal data is retained no longer than necessary for the purposes for which it was collected.
2. Retention Periods by Category
Detailed retention periods are available in the Data Retention Policy. A summary is provided below:
- Account Data: Retained for the duration of the relationship plus 3-5 years for legal obligations.
- Technical and Usage Data: Retained for a maximum of 2 years after last interaction, unless required for longer periods.
- Financial Data: Retained for the duration of the relationship and 6 years for legal obligations.
- Communication Data: Retained for a maximum of 3 years after resolution of support requests.
- Product-Specific Data: Retention periods outlined in product-specific documentation.
Data Security
1. Security Measures
We implement encryption, access controls, audit logs, incident response plans, regular security audits, data minimization, and secure authentication.
2. Data Protection Impact Assessments
DPIAs are conducted for high-risk processing activities to identify and mitigate risks. Contact the data protection contact for more information.
International Data Transfers
If data is transferred outside the EEA, adequate safeguards such as Standard Contractual Clauses or adequacy decisions are implemented.
Automated Decision-Making and Profiling
We do not use automated decision-making that produces legal or significant effects. Profiling activities are conducted for service optimization and marketing segmentation without legal or significant effects. You may object to profiling based on legitimate interests.
1. Right to Object to Profiling
Contact the data protection contact at privacy@revzper.com to object to profiling based on legitimate interests.
Ref: GDPR Art. 21
Updates to This Policy
This policy may be updated periodically. All updates are published on our website and notified via email or in-app notification. Material changes are communicated at least 30 days prior to implementation.
Governing Law and Jurisdiction
This policy is governed by French law. Disputes are subject to the exclusive jurisdiction of the courts of Paris, France.
Contact Us
For questions or concerns about this policy, contact the data protection contact at privacy@revzper.com or write to revzper SAS at 123 Rue de la République, 75002 Paris, France.
Product Access Points
For product-specific information, see https://euphile.eu/. The products of the platform are Solon, Vauban, Nassau, Leonardo, Atlas, Plutus, Tzu and Richelieu.